Legal
Privacy Policy
Hairset puts a new haircut on your own face. That only works if you trust us with your photo, so this policy is written to be read — plainly, and completely.
Last updated:
1. Who we are and what this covers
This Privacy Policy explains how Hairset (“Hairset”, “we”, “us”) collects, uses and protects information when you use the Hairset mobile application (the “App”), the website at https://hairset.app (the “Site”) and related services (together, the “Service”). It applies to everyone who uses the Service, wherever they are located.
We act as the data controller for the personal data described here. Apple Inc. processes your payment separately as described in Section 6.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Photos | The selfie you take or pick from your library; reference photos you upload with “Bring Your Own Photo”. | You |
| Renders | The AI-generated images of you with a new haircut, color or beard, and the looks you save, compare or share. | Generated by the Service |
| Analysis results | Face shape, skin undertone / color season and hair texture derived from your selfie, and the look recommendations built from them. | Generated by the Service |
| Account | An anonymous account created for your device on first launch; if you choose Sign in with Apple, the identifier Apple provides and, if you share it, your name and (possibly relayed) email address. | Your device; Apple |
| Preferences | Hair texture, what you are looking for, the “For her / For him / Everyone” side you pick, saved looks, dismissed announcements. | You |
| Purchases | Which plan or look pack you bought, when it renews or expires, and how many looks you have used. We do not receive your card number. | Apple; our purchase provider |
| Technical | A per-install device identifier, app version, device model and OS version, request logs (IP address, timestamps, endpoints) kept for security and debugging. | Your device |
We do not collect your contacts, precise location, health data, or advertising identifiers, and the App contains no third-party advertising or analytics SDKs.
3. Your photos and renders
Purpose only. Your selfie is uploaded to our servers for one reason: to render the looks you ask for and, if you use Ask AI, to read your face shape and color season. It is not used to train any AI model, it is not shown to other users, and it is not used for advertising.
Not facial recognition. The analysis estimates proportions (for example “oval face”, “warm undertone”). We do not create a biometric template, we do not attempt to identify you or anyone else, and we do not match faces across photos or users.
Automatic deletion. Source selfies are permanently deleted from our servers within 24 hours of upload unless you save a look rendered from them, in which case the selfie is kept only for as long as that saved look exists so you can re-render and compare. Renders you do not save expire in the same way. You can delete your current photo immediately from the You tab.
Sharing is your call. When you tap Share or Save to Photos, the image leaves the Service through your device’s share sheet or photo library under your control. We do not post anything on your behalf.
4. How we use information
- To render looks, run the analysis, and show your results, saved looks and comparisons.
- To create and maintain your account, keep your looks balance accurate, and restore purchases.
- To personalize the catalog (for example showing the men’s side by default after you pick “For him”).
- To provide support and respond to your requests.
- To keep the Service secure, prevent abuse and debug problems.
- To comply with law and enforce our Terms of Use.
Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract (rendering the looks you request); your consent (processing your photo, which you may withdraw by deleting it or your account); and our legitimate interests in security, fraud prevention and improving the Service in ways that do not involve your photos.
5. AI processing and service providers
Renders and analyses are produced by generative AI models. To do that, the photo you submit and a text description of the look are sent to our AI model provider (currently Google LLC’s Gemini API) over an encrypted connection. Under the terms we use, the provider does not use your content to train its models and does not retain it beyond the time needed to return the result and meet abuse-monitoring obligations.
We also rely on a small number of providers who process data on our behalf and only on our instructions:
- Hosting — servers that run the Service and store photos and renders for the retention periods above.
- Purchases — Apple (App Store / StoreKit) handles payment; Superwall Inc. processes purchase events so we can keep your plan and looks balance in sync. They receive a pseudonymous account identifier and purchase details, never your photos.
- Sign in with Apple — Apple authenticates you if you choose this option.
6. When we share information
We do not sell or rent personal data, and we do not share it with data brokers or advertisers. We share information only:
- with the service providers in Section 5, to operate the Service;
- with Apple, to the extent required for purchases, subscriptions and refunds;
- when you choose to share a render or stylist card yourself;
- if required by law, subpoena or court order, or to protect the rights, safety and integrity of the Service or its users;
- in connection with a merger, acquisition or sale of assets, in which case this policy continues to apply to your data.
7. How long we keep it
| Data | Retention |
|---|---|
| Source selfie (no saved looks) | Deleted within 24 hours of upload |
| Source selfie (with saved looks) | Until you remove the last saved look from it, delete the photo, or delete your account |
| Unsaved renders | Expire automatically with the selfie they came from |
| Saved looks, analysis results, preferences | Until you delete them or your account |
| Account and purchase records | While your account exists; afterwards only what tax, accounting or dispute rules require |
| Server logs | Up to 30 days |
8. Your choices and rights
- Delete your photo at any time: You tab → Your photo → Delete now. Renders made from it that you did not save are removed too.
- Delete your account and everything in it: You tab → Delete account. This is immediate and cannot be undone. See Delete your account for details and an email fallback.
- Access, correct, export or restrict your data, or object to processing, by emailing privacy@hairset.app. We answer within 30 days and may ask you to verify the request from the device or Apple ID linked to the account.
- Withdraw consent for photo processing by deleting your photo; the rest of the Service keeps working.
- Complain to your local data protection authority if you believe we have not handled your data lawfully. We would appreciate the chance to address it first.
Residents of California and other US states with privacy laws have the right to know, delete and correct personal information, and to opt out of “sales” or “sharing” — we do neither. We do not discriminate against you for exercising these rights.
9. Security
All traffic between the App and our servers is encrypted with TLS. Photos and renders are stored on access-controlled servers and are reachable only through authenticated, per-account links. Authentication tokens are kept in your device’s secure keychain. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the relevant authorities as the law requires.
10. Children
The Service is intended for people aged 13 or older (16 where local law sets that age for consent). We do not knowingly collect personal data from younger children. The “Kids” catalog exists so that a parent or guardian can preview styles on a photo of their own child; that photo is treated exactly like any other selfie, including the 24-hour deletion, and you can delete it at any time. If you believe a child has used the Service without permission, contact us and we will delete the data.
11. International transfers
Our servers and providers may be located outside the country you live in, including the United States and the European Union. Where required, we rely on recognised safeguards such as the European Commission’s Standard Contractual Clauses to protect data transferred abroad.
12. Changes to this policy
We may update this policy as the Service evolves. The date at the top shows the latest revision. For material changes we will notify you in the App before they take effect. Continuing to use the Service after that date means you accept the updated policy.
13. Contact
Privacy questions and requests: privacy@hairset.app
General support: support@hairset.app